UD Computer Sleuth: Undergraduate student plays a leading role in exposing the Melissa virus

Contact: Ginger Pinholster, (302) 831-6408, [email protected]

On the evening of March 26, 19-year-old Rishi Khan was cruising the Internet from his University of Delaware residence hall room when he spotted a message from fellow coder Ralph Smith, who wanted to unlock the twisted programming secrets of the "Melissa" computer virus.

Soon, the unassuming cybersleuth--already a senior at UD after only two years--was receiving attention from national publications such as the April 12 Newsweek, which describes his role in exposing the most contagious computer virus ever concocted.

Khan, of Wilmington, Del., was browsing an antivirus newsgroup site when he read Richard Smith's message. The president of Phar Lap Software of Cambridge, Mass., Smith and a Swedish researcher were investigating similarities between Melissa and other viruses created by a computer vandal using the name, "VicodinES" (a type of narcotic painkiller.)

In no time, Khan had determined that Melissa was extremely similar to the Shiver virus, created by a vandal known as "ALT-F11."

Meanwhile, because Microsoft programs embed a "digital fingerprint" called a GUID in all the work produced on a particular computer, on March 28, Richard Smith traced the Melissa virus to a David L. Smith of Aberdeen Township, N.J., whose name he passed along to the Federal Bureau of Investigation (FBI).

After America Online's technical team also reportedly traced the Melissa virus to David Smith, he was arrested April 1, and now faces up to 40 years in prison and a $480,000 fine. According to one source cited by Newsweek, the Melissa virus may have been named after a topless dancer in Florida.

Khan's persistent research made it possible to better understand the Melissa virus, which should prove useful to authorities, Richard Smith says.

"He's a very bright kid," the Phar Lap Software executive says. "He obviously knows how to do a lot of stuff with network programming. He solved a lot of things even I didn't see, and I'm 45!"

Khan's research professor at UD, John Elias, an associate professor of electrical and computer engineering, agrees. "He's a remarkable student, one of the best undergraduates that I've seen in my 10 years at UD," says Elias, head of the University's Neuromorphic Systems Laboratory. "He has a very broad, diverse group of interests."

Identifying Melissa's author was "sort of a race," involving three separate teams of investigators, working in parallel, Richard Smith says. His group of cybersleuths--including Khan--formed one group. The FBI and New Jersey state authorities were the other two, simultaneously searching for a suspect.

Unleashed March 26, Melissa wreaked havoc for computer users for about a week, until antivirus companies distributed a cure. Described by Newsweek writer Steven Levy as "a silicon social disease," the Melissa virus alerts electronic mail users to "an important message," then delivers a file containing the passwords to pornographic web sites. At the same time, Melissa grabs the first 50 names from the victim's address book and begins sending the same embarrassing message to friends and colleagues.

Could the suspect in the Melissa case, David L. Smith, be the notorious computer vandal, VicodinES? Is he also the hacker, ALT-F11, author of the Shiver virus?

Khan offers this response: "His name comes up a lot in the files that VicodinES wrote, and since America Online did a hardware trace and came up with the same person, that seems to incriminate him as VicodinES. We're still investigating ALT-F11. The Shiver virus, created by ALT-F11, had many similarities to Melissa."

Khan says his primary interest is in artificial intelligence. His research professor, John Elias, says Khan assists him in using integrated circuit technology to build "silicon neurons," which mimic human nervous systems. The work may be useful in developing advanced robotics systems, Elias says.

Khan's father, Subhotosh Khan, is a mechanical engineer. His mother, Eileen Khan, graduated from UD with a degree in computer and information sciences. Her work involves teaching children to use computing technologies, Khan says.

NOTE TO REPORTERS: Photograph of Khan is available.

April 12, 1999